What is CVE-2026-18698?
A vulnerability in MongoDB Server (CVE-2026-18698) could allow an authenticated user with a limited database-scoped role to perform actions on protected system collections that require more specific privileges. This may lead to the exposure of collection metadata and, depending on certain deployment configurations, further unauthorized access. Upgrading MongoDB Server to the latest patched version is strongly recommended.
Azərbaycanca: MongoDB Server-də müəyyən edilmiş bu boşluq (CVE-2026-18698) autentifikasiya olunmuş və məhdud verilənlər bazası əhatəli rola malik istifadəçiyə xüsusi imtiyaz tələb edən qorunan sistem kolleksiyaları üzərində əməliyyat aparmağa imkan verir. Bu, kolleksiya meta-məlumatlarının ifşasına səbəb ola bilər. Təsirə məruz qalmamaq üçün MongoDB Server-i ən son təhlükəsizlik yeniləmələrinə qədər yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: MongoDB
FAQ2
What type of data can an attacker gain access to in MongoDB Server by exploiting CVE-2026-18698?
This vulnerability may lead to the exposure of collection metadata.
Does an attacker need to be authenticated to exploit CVE-2026-18698?
Yes, this vulnerability can be exploited by an authenticated user with a limited database-scoped role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.